All guided builds

Guided buildadvanced8 steps~25 min5 devices

Two providers, one eBGP session

Connect two autonomous systems, bring up an eBGP session between their border routers, and announce each provider's customer blocks to the other.

What you'll be able to do: Two autonomous systems exchange their customer prefixes over one eBGP session: each provider learns the other's blocks as B routes with the far AS in the path, and a brand-new customer block becomes reachable from the other network with one `network` line and no change on the far side.

Topics: BGP · eBGP · Dynamic routing · Routing tables

What you'll build

Step by step

  1. 1. Stand up the first provider

    Drag a router and a server onto the canvas, cable the server into Gi0/0 and name the router ISP-A. This provider is autonomous system 65001 and hosts 198.51.100.0/24 — a block the rest of the internet only finds if ISP-A tells it the block exists.

    • Cable WEB-A Eth0 ↔ ISP-A Gi0/0

    On ISP-A — Name the first provider's router and address its customer LAN

    enable
    configure terminal
    hostname ISP-A
    interface Gi0/0
    ip address 198.51.100.1 255.255.255.0
    no shutdown
    exit
    end

    On WEB-A — Name the server and set address, mask and gateway

    hostname WEB-A
    ipconfig Eth0 198.51.100.10 255.255.255.0 198.51.100.1

    Check: run show ip route on ISP-A and look for C 198.51.100.0/24 is directly connected, Gi0/0.

    Why: An autonomous system is a network run by one organisation under one routing policy — a provider, a university, a large company. Between autonomous systems the internet runs a single protocol, BGP, and the thing it carries is a prefix like this /24.

  2. 2. Stand up the second provider

    A second router and a second autonomous system: ISP-B is AS 65002 and hosts 203.0.113.0/24, with a customer's PC on it. Two networks, each complete on its own, neither aware the other exists.

    • Cable PC-B Eth0 ↔ ISP-B Gi0/0

    On ISP-B — Name the second provider's router and address its customer LAN

    enable
    configure terminal
    hostname ISP-B
    interface Gi0/0
    ip address 203.0.113.1 255.255.255.0
    no shutdown
    exit
    end

    On PC-B — Name the customer PC and point it at its gateway

    hostname PC-B
    ipconfig Eth0 203.0.113.10 255.255.255.0 203.0.113.1

    Check: run show ip route on ISP-B and look for C 203.0.113.0/24 is directly connected, Gi0/0.

    Why: AS numbers are handed out by the same registries that hand out IP blocks. 64512 to 65534 are private — the AS equivalent of RFC 1918 space — which is why labs, and customers that connect to a single provider, use numbers from that range.

  3. 3. Cable the interconnect

    Run a serial cable between the two routers' Se0/0/0 ports and number it 10.0.0.0/30: .1 for ISP-A, .2 for ISP-B. The two border routers can ping each other now — but WEB-A still can't reach PC-B, because a cable between two networks is not a route between them.

    • Cable ISP-A Se0/0/0 ↔ ISP-B Se0/0/0 (serial)

    On ISP-A — Address ISP-A's end of the interconnect

    enable
    configure terminal
    interface Se0/0/0
    ip address 10.0.0.1 255.255.255.252
    no shutdown
    exit
    end

    On ISP-B — Address ISP-B's end of the interconnect

    enable
    configure terminal
    interface Se0/0/0
    ip address 10.0.0.2 255.255.255.252
    no shutdown
    exit
    end

    Check: run show ip route on ISP-A and look for C 10.0.0.0/30 is directly connected, Se0/0/0.

    Why: Providers meet at private interconnects or exchange points and number the link between them by agreement. The link is plumbing: it exists so the two border routers can talk, and neither provider needs to tell the world about it.

  4. 4. Open BGP at ISP-A — and wait

    Start BGP for AS 65001, name ISP-B's address as a neighbour in AS 65002, and announce ISP-A's customer block. Then read `show ip bgp summary`: the neighbour sits in Active. BGP never goes looking for peers — it opens a session only to an address you name, and nothing at 10.0.0.2 is answering yet.

    On ISP-A — Configure ISP-A's half of the peering and announce its block

    enable
    configure terminal
    router bgp 65001
    bgp router-id 1.1.1.1
    neighbor 10.0.0.2 remote-as 65002
    network 198.51.100.0 mask 255.255.255.0
    end

    On WEB-A — Try the other provider's customer — this one is supposed to fail

    ping 203.0.113.10

    Check: run show ip bgp summary on ISP-A and look for 10.0.0.2 4 65002 0 0 1 0 0 00:00:00 Active.

    Why: Unlike OSPF, BGP sends no hellos to find neighbours: every peering is configured by hand at both ends and runs over a TCP session to port 179. One end configured is half a handshake, so the neighbour stays Active — still trying to connect — until the other side agrees.

  5. 5. Open BGP at ISP-B — the session comes up

    Mirror it on ISP-B: AS 65002, neighbour 10.0.0.1 in AS 65001, and a `network` line for its own block. The session goes Established, each router receives the other's prefix, and WEB-A reaches PC-B across two autonomous systems.

    On ISP-B — Configure ISP-B's half of the peering and announce its block

    enable
    configure terminal
    router bgp 65002
    bgp router-id 2.2.2.2
    neighbor 10.0.0.1 remote-as 65001
    network 203.0.113.0 mask 255.255.255.0
    end

    On WEB-A — Cross from one autonomous system into the other

    ping 203.0.113.10

    Check: run show ip bgp summary on ISP-A and look for 10.0.0.2 4 65002 0 0 1 0 0 00:00:00 1.

    Why: Each side now announces what it is responsible for and installs what it hears. `show ip bgp` on ISP-A lists 203.0.113.0/24 with the path 65002: BGP records every AS a route has crossed, which is one of the ways it chooses between routes and how it rejects a route that would loop back into an AS it already passed through.

  6. 6. Take on a new customer at ISP-B

    ISP-B signs a second customer on a different block, 192.0.2.0/24. Cable a PC into ISP-B's Gi0/1 and address the port and the PC. Inside ISP-B everything works at once: the new customer reaches its gateway, and ISP-B has the block in its table.

    • Cable PC-B2 Eth0 ↔ ISP-B Gi0/1

    On ISP-B — Address the new customer's LAN on ISP-B

    enable
    configure terminal
    interface Gi0/1
    ip address 192.0.2.1 255.255.255.0
    no shutdown
    exit
    end

    On PC-B2 — Name the new customer's PC and point it at ISP-B

    hostname PC-B2
    ipconfig Eth0 192.0.2.10 255.255.255.0 192.0.2.1

    Check: run show ip route on ISP-B and look for C 192.0.2.0/24 is directly connected, Gi0/1.

    Why: A connected network is in the provider's own table the moment the interface comes up — but that is ISP-B's table, not the internet's. What another autonomous system can reach is decided by what this one announces.

  7. 7. The other provider can't see it yet

    Change nothing — look. Ping PC-B2 from WEB-A and it fails at ISP-A, which has no route to 192.0.2.0/24. ISP-B announces exactly the prefixes it was told to announce, and nobody has told it about this one.

    On WEB-A — Try the new customer from the other provider

    ping 192.0.2.10

    On ISP-B — See what ISP-B is announcing

    enable
    show ip bgp

    Check: run show ip route 192.0.2.10 on ISP-A and look for % Network not in table.

    Why: BGP never announces a network just because it is connected. A provider announces exactly the prefixes it is prepared to carry traffic for — announcing the wrong one by accident is how the route leaks that make the news begin.

  8. 8. Announce the new block

    One more `network` line under ISP-B's BGP process. The prefix is already in ISP-B's table, so it is announced at once: ISP-A installs a second B route and WEB-A reaches PC-B2 — with not a single change typed on ISP-A.

    On ISP-B — Announce the new customer's block to ISP-B's peer

    enable
    configure terminal
    router bgp 65002
    network 192.0.2.0 mask 255.255.255.0
    end

    On WEB-A — Reach the new customer across the AS boundary

    ping 192.0.2.10

    Check: run show ip bgp on ISP-A and look for 192.0.2.0/24 10.0.0.2.

    Why: That is the whole contract between providers: each announces what it is responsible for, each installs what it hears, and neither configures the other's customers. It scales to the entire internet because nobody ever types a route to somebody else's network.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
Two providers, one eBGP session — step-by-step network lab · NetForge-AI